<!--

    Copyright (c) 1997, 2018 Oracle and/or its affiliates. All rights reserved.

    This program and the accompanying materials are made available under the
    terms of the Eclipse Public License v. 2.0, which is available at
    http://www.eclipse.org/legal/epl-2.0.

    This Source Code may also be made available under the following Secondary
    Licenses when the conditions for such availability set forth in the
    Eclipse Public License v. 2.0 are satisfied: GNU General Public License,
    version 2 with the GNU Classpath Exception, which is available at
    https://www.gnu.org/software/classpath/license.html.

    SPDX-License-Identifier: EPL-2.0 OR GPL-2.0 WITH Classpath-exception-2.0

-->

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml"
      xmlns:h="http://java.sun.com/jsf/html"
      xmlns:f="http://java.sun.com/jsf/core">
    <head>
        <meta http-equiv="Contexnt-Type" content="text/html; charset=UTF-8"/>
        <title></title>
    </head>

    <body>
        <f:view>
            <h:form id="testForm">
                Put the following input and JavaScript will be executed.<br/>
                <table border="2">
                    <td>
                        --&gt;&lt;script&gt;alert('JSF Security hole!!')&lt;/script&gt;
                    </td>
                </table>
                <!-- #{outputTextScript2Bean.comment}  -->
                <br/>
                <h:inputTextarea id="textarea" cols="40" rows="6" value="#{outputTextScript2Bean.comment}"/><br/>
                <br/>
                <h:commandButton id="button" type="submit" value="test"/><br/>
                <br/>
            </h:form>
        </f:view>
    </body>
</html>
